Upgrade to 2.36.7 for Focal and Jammy
Bug #1970779 reported by
Luís Infante da Câmara
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
wpewebkit (Ubuntu) |
Incomplete
|
Medium
|
Unassigned | ||
Focal |
Confirmed
|
Undecided
|
Spyros Seimenis | ||
Jammy |
Confirmed
|
Undecided
|
Spyros Seimenis |
Bug Description
I want to upgrade the versions in Focal and Jammy to 2.36.7 to fix security issues and other bugs, as well as adding features that increase compatibility with current websites.
The version in Focal is affected by all vulnerabilities listed below.
The version in Jammy is vulnerable to
CVE-2022-22677, CVE-2022-26700, CVE-2022-26709, CVE-2022-26710, CVE-2022-26716, CVE-2022-26717, CVE-2022-26719, CVE-2022-30293, CVE-2022-30294, CVE-2022-32792, CVE-2022-32816 and CVE-2022-32893.
Debian released an advisory on April 8.
CVE References
- 2020-13543
- 2020-13558
- 2020-13584
- 2020-13753
- 2020-27918
- 2020-29623
- 2020-3899
- 2020-9802
- 2020-9803
- 2020-9805
- 2020-9806
- 2020-9807
- 2020-9843
- 2020-9850
- 2020-9862
- 2020-9893
- 2020-9894
- 2020-9895
- 2020-9915
- 2020-9925
- 2020-9947
- 2020-9948
- 2020-9951
- 2020-9952
- 2020-9983
- 2021-1765
- 2021-1788
- 2021-1789
- 2021-1799
- 2021-1801
- 2021-1817
- 2021-1820
- 2021-1825
- 2021-1826
- 2021-1844
- 2021-1870
- 2021-1871
- 2021-21775
- 2021-21779
- 2021-21806
- 2021-30661
- 2021-30663
- 2021-30665
- 2021-30682
- 2021-30689
- 2021-30720
- 2021-30734
- 2021-30744
- 2021-30749
- 2021-30758
- 2021-30795
- 2021-30797
- 2021-30799
- 2021-30809
- 2021-30818
- 2021-30823
- 2021-30836
- 2021-30846
- 2021-30848
- 2021-30849
- 2021-30851
- 2021-30858
- 2021-30884
- 2021-30887
- 2021-30888
- 2021-30889
- 2021-30890
- 2021-30897
- 2021-30934
- 2021-30936
- 2021-30951
- 2021-30952
- 2021-30953
- 2021-30954
- 2021-30984
- 2021-42762
- 2021-45481
- 2021-45482
- 2021-45483
- 2022-22589
- 2022-22590
- 2022-22592
- 2022-22594
- 2022-22620
- 2022-22624
- 2022-22628
- 2022-22629
- 2022-22637
- 2022-22662
- 2022-22677
- 2022-26700
- 2022-26709
- 2022-26710
- 2022-26716
- 2022-26717
- 2022-26719
- 2022-30293
- 2022-30294
- 2022-32792
- 2022-32816
- 2022-32893
no longer affects: | webkitgtk (Ubuntu) |
no longer affects: | webkit2gtk (Ubuntu) |
summary: |
- Multiple vulnerabilities + Multiple vulnerabilities in Bionic, Focal and Impish |
description: | updated |
description: | updated |
Changed in wpewebkit (Ubuntu): | |
status: | New → Incomplete |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
information type: | Private Security → Public Security |
summary: |
- Multiple vulnerabilities in Bionic, Focal and Impish + Multiple vulnerabilities in Focal and Impish |
description: | updated |
Changed in wpewebkit (Ubuntu): | |
status: | Incomplete → In Progress |
assignee: | nobody → Luís Cunha dos Reis Infante da Câmara (luis220413) |
Changed in wpewebkit (Ubuntu): | |
status: | In Progress → Fix Committed |
description: | updated |
description: | updated |
summary: |
- Multiple vulnerabilities in Focal and Impish + Multiple vulnerabilities in Focal, Impish and Jammy |
Changed in wpewebkit (Ubuntu): | |
status: | Fix Committed → In Progress |
Changed in wpewebkit (Ubuntu): | |
status: | Fix Committed → New |
summary: |
- Multiple vulnerabilities in Focal, Impish and Jammy + Upgrade to 2.36.3 for Focal, Impish and Jammy |
description: | updated |
Changed in wpewebkit (Ubuntu): | |
assignee: | Luís Cunha dos Reis Infante da Câmara (luis220413) → nobody |
Changed in wpewebkit (Ubuntu): | |
importance: | Undecided → Medium |
description: | updated |
description: | updated |
summary: |
- Upgrade to 2.36.4 for Focal, Impish and Jammy + Upgrade to 2.36.4 for Focal and Jammy |
description: | updated |
description: | updated |
description: | updated |
Changed in wpewebkit (Ubuntu): | |
status: | Fix Committed → In Progress |
assignee: | nobody → Luís Cunha dos Reis Infante da Câmara (luis220413) |
summary: |
- Upgrade to 2.36.6 for Focal and Jammy + Upgrade to 2.36.7 for Focal and Jammy |
description: | updated |
Changed in wpewebkit (Ubuntu): | |
assignee: | Luís Infante da Câmara (luis220413) → nobody |
To post a comment you must log in.
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https:/ /wiki.ubuntu. com/SecurityTea m/UpdateProcedu res